Skip to content
Shield AI logo
Active

Staff Systems Administrator (R5995)

Shield AI
LondonOn sitefull-timeStaffPosted 13 days ago

About the role

Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedIn, X, Instagram, and YouTube. Job Description: Shield AI is seeking a highly autonomous Staff Systems Administrator to serve as the accountable technical owner for enterprise IT infrastructure and end-user computing within a dedicated, security-sensitive entity environment. This senior individual contributor will design, implement, operate, secure, and continuously improve on-premises systems, cloud platforms, identity services, networks, and endpoints while preserving required legal, operational, information-security, and access boundaries. The role combines deep infrastructure ownership with hands-on service delivery. The successful candidate will translate security and compliance requirements into durable technical controls, maintain audit-ready evidence, drive equipment and endpoint hardening, and deliver resilient support to engineering and business teams with minimal oversight. What you'll do: Infrastructure Ownership (On-Prem & Cloud) - Own and operate on-premises and cloud infrastructure, including physical and virtual servers, storage, backup platforms, identity services, core network services, and enterprise applications. - Administer Azure and/or AWS environments with responsibility for availability, capacity, performance, monitoring, secure configuration, backup, and disaster-recovery readiness. - Define technical roadmaps, identify operational risks, and independently drive modernization, standardization, scalability, and resilience improvements. - Maintain accurate architecture diagrams, inventories, operating procedures, recovery documentation, configuration records, and service ownership information. - Plan and execute infrastructure changes using disciplined change, testing, rollback, and post-implementation review practices. Firewalled Entity and Segmented-Environment Support - Operate technology services for a dedicated legal or operating entity with explicit separation of systems, identities, data, administration, suppliers, and access from other corporate environments where required. - Implement and maintain approved trust boundaries, network segmentation, firewall policies, secure remote access, administrative tiers, and controlled cross-entity connectivity. - Ensure data, devices, accounts, cloud resources, and third-party access remain within authorized entity, contractual, regulatory, and data-residency boundaries. - Partner with Security, Legal, Compliance, Privacy, and corporate IT teams to translate entity-specific obligations into practical controls, operating procedures, and evidence. - Document and periodically validate boundary controls, data flows, privileged access paths, exceptions, and intercompany dependencies; escalate gaps and drive remediation to closure. - Support local business continuity and operational autonomy while aligning with approved global architecture, security standards, and governance. Security, Compliance, and Systems - Establish, implement, and maintain secure configuration baselines for Windows, macOS, Linux, servers, network devices, cloud services, and endpoint-management platforms using recognized frameworks and vendor guidance. - Own patching and vulnerability-remediation workflows, including asset coverage, risk-based prioritization, remediation timelines, exception documentation, validation, and status reporting. - Administer and validate endpoint protections such as full-disk encryption, EDR/XDR, host firewall, secure boot, application controls, device compliance, removable-media controls, and least-privilege configurations. - Harden identity and administrative access through role-based access control, multifactor authentication, privileged-access separation, conditional access, service-account governance, and periodic access reviews. - Maintain logging, alerting, time synchronization, configuration monitoring, backup protection, and security telemetry needed for detection, investigation, and auditability. - Collect and maintain audit-ready evidence; support internal and external audits, control assessments, security reviews, customer requirements, and remediation plans. - Participate in incident response, containment, recovery, root-cause analysis, and corrective actions for infrastructure and endpoint security events. - Manage technical risks and policy exceptions transparently, including compensating controls, accountable owners, expiration dates, and closure plans. Identity, Endpoint, and Service Delivery - Administer Active Directory and Entra ID or equivalent identity platforms, including user and group lifecycle, authentication, authorization, federation, and policy enforcement. - Manage Windows, macOS, and Linux endpoints through Intune, Jamf, or equivalent tooling, ensuring secure provisioning, configuration compliance, software deployment, inventory accuracy, and timely retirement. - Lead onboarding and offboarding activities, including device provisioning, access configuration, license assignment, asset recovery, and compliance validation. - Provide advanced troubleshooting and escalation support for employees, engineering systems, lab environments, collaboration services, and secure connectivity. - Own IT asset lifecycle, software licensing, vendor coordination, procurement support, warranty management, and secure equipment disposal. - Use scripting and automation to improve consistency, reduce manual effort, strengthen controls, and provide meaningful operational and compliance reporting. - Contribute reusable infrastructure patterns, standards, and documentation that can scale across comparable international entity environments. Required qualifications: - 8 + years of experience in systems administration, infrastructure engineering, enterprise IT operations, or a closely related discipline. - Demonstrated success independently owning production IT infrastructure and end-user environments in a complex, regulated, segmented, or security-sensitive organization. - Strong hands-on expertise with Windows, macOS, and Linux; server administration and virtualization; Azure and/or AWS; and Active Directory and Entra ID or equivalent identity platforms. - Practical experience implementing system and endpoint hardening, configuration baselines, patch management, vulnerability remediation, encryption, endpoint detection and response, and least-privilege controls. - Experience supporting security or compliance programs and producing evidence for audits, assessments, or customer and regulatory requirements. - Strong networking knowledge, including TCP/IP, DNS, DHCP, VLANs, routing, VPNs, network segmentation, firewall policy, and secure remote access. - Experience with endpoint management platforms such as Intune, Jamf, or equivalent, including compliance policy and device lifecycle management. - Experience implementing and testing monitoring, backup, disaster recovery, and business-continuity capabilities. - Excellent documentation, prioritization, risk communication, and stakeholder-management skills, with the ability to drive outcomes under limited supervision. - Ability to support time-sensitive operational needs and participate in planned after-hours maintenance or incident response when required. Preferred qualifications: - Experience supporting a firewalled, ring-fenced, subsidiary, joint-venture, sovereign, or otherwise separately governed entity environment. - Experience supporting engineering, R&D, aerospace, defense, manufacturing, or other mission-critical technical teams. - Working knowledge of recognized security and compliance frameworks such as CIS Controls and Benchmarks, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent local and contractual standards. - Experience with security tooling such as SIEM, vulnerability-management platforms, privileged-access management, data-loss prevention, certificate management, or network-access control. - Experience supporting isolated, air-gapped, export-controlled, or data-residency-restricted systems. - Scripting and automation experience using PowerShell, Bash, Python, APIs, infrastructure as code, or configuration-management tooling. - Familiarity with GitHub, Azure DevOps, CI/CD environments, and secure engineering workflows. - Relevant certifications such as Microsoft, AWS, VMware, Cisco, CompTIA Security+, CISSP, CISM, GIAC, ITIL, or equivalent. #LI-SL1 #LD   Our international teammates receive a comprehensive total rewards package aligned to your country office location. For full details on compensation and benefits, please consult your talent acquisition partner.

Similar roles